Hacker News new | ask | show | jobs
by andai 16 days ago
Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS.

I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS.

So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at least give you the option of installing all that crap but that would seem to defeat the purpose in this case.)

But more broadly I'm not sure I understand the relevance in this particular context. The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario? (Ok I suppose half the stuff on the Play store is spyware so maybe it's more realistic than I'm thinking...)

5 comments

> So I'm assuming Graphene is at least as strict as that?

GrapheneOS is a privacy and security hardened OS. LineageOS and CyanogenMod aren't in that space. GrapheneOS preserves the standard privacy and security features and updates of the Android Open Source Project as a baseline. It greatly improves privacy and security with major privacy and security features along with much better privacy/security updates. It keeps up with the major OS updates including having a release based on Android 17 since the day it was released (2026-06-16).

> Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS.

GrapheneOS is a production quality OS with around 15 people paid to work on it. It's not a hobbyist project. We've never used the term custom ROM since it isn't accurate and propagates misconceptions. It's best to avoid it.

> The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario?

Yes, stalkerware is very common and there are a bunch of apps marketed for this purpose. It's helpful to get a new phone set up from scratch without the same accounts or automatically restoring any data on it. This can be a GrapheneOS phone but it doesn't particularly need to be. It's not GrapheneOS recommending itself for this purpose. There are an assortment of privacy and security features relevant to this in standard Android 17 and in the features added by GrapheneOS but nothing essential to this. GrapheneOS makes sense as a general choice for a new phone for many people due to being a highly usable, compatible, private and secure device but we're not specifically recommending it for being who are victims of stalkerware ourselves.

> We've never used the term custom ROM since it isn't accurate and propagates misconceptions. It's best to avoid it.

It's a ROM (in the phone sense), and it's not stock (so installing it is a customization). In what way is it not a custom ROM?

> It's a ROM (in the phone sense)

There are multiple ROMs involved but GrapheneOS isn't one. There's an SoC boot ROM which loads SoC firmware from the SSD, verifies it and transfers control to it. The littlekernel-based firmware stage which loads GrapheneOS isn't a ROM. GrapheneOS and most of the SoC firmware are simply stored on SSD partitions. There are A/B partitions for both the SoC firmware and the OS on the SSD. Installing (flashing) GrapheneOS involves writing out images to those partitions on the SSD and erasing an existing data partition which also happens as part of unlocking or locking the device. Those partitions aren't read-only from an OS perspective. Verified boot secures what's stored on those, not any form of hardware or firmware level write protection.

There are also boot ROMs for other hardware components. Many of those are responsible for receiving firmware uploaded by the OS to the hardware component at boot, verifying it and transferring control to it. The secure element has separate persistent firmware with a separate verified boot process since the OS isn't allowed to update it until the Owner user has successfully authenticated so it needs persistent firmware. Other hardware components mostly don't need persistent firmware and it's more secure if they don't have it.

> it's not stock

GrapheneOS will be available as the stock OS on multiple Motorola Mobility devices based on our partnership. It won't necessarily be available as the stock OS when the official support for it launches since it's not one of the minimum requirements but it's planned.

> so installing it is a customization

It's a separate OS forked from the Android Open Source Project but this terminology gives many people the incorrect impression that it's a modification of the stock OS. It leads to many people asking questions about what it removes from the stock OS and believing we removed Google integration when that was never present in the baseline. There are a lot of misconceptions which are propagated by this terminology. We don't use it and think it only serves to create unnecessary confusion and misconceptions.

> In what way is it not a custom ROM?

It was just never accurate terminology for forks of the Android Open Source Project on modern devices. The terminology originates from phone modding prior to Android and there was a time it made sense. It hasn't made sense for a long time.

Zero Google services are shippsx by default, but you can install Play Store and Services in a sandbox and it has minimal privacy problems, depending on the permissions you give it.

Their docs are really good, not only for their phone but for learning about privacy and security: https://grapheneos.org

You could still install an app that spies on you on grapheneos because it has 99.99% android app compatibility, so if you gave an app designed for spying the relevant permissions, it would still be able to spy. No way it could hide location indicator or anything like that, but I doubt it could do that on other OSes (don't quote me on other OSes).

> The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario?

Yes, stalkerware is an entire genre of software and it is designed for exactly this purpose.

How “stalkerware” apps are letting abusive partners spy on their victims https://www.technologyreview.com/2019/07/10/134249/stalkerwa...

The Abuser in Your Pocket: How Stalkerware Threatens Women’s Privacy https://safeescape.org/stalkerware-threatens-womens-privacy/

'I thought I'd been microchipped': How abusers spy on partners with 'parental control' apps https://news.sky.com/story/i-thought-id-been-microchipped-ho...

A web search for the term will turn up many more results. Graphene OS's hardening against exploits, compared to the abysmal record of Android vendors, gives much better odds against any of these apps being able to run with elevated privileges, which means Android's sandboxing is effective.

(Happy Graphene OS user of many years here.)

Happy GrapheneOS user here as well, but...

I am having a hard time believing your first link, which says:

> In Anna’s case, stalkerware was disguised as a picture message, sent to her by the man she was dating (let’s call him David), just a few weeks after they met. She was then under constant surveillance for about two years

That sounds like an NSO-level attack, right? I doubt abusers routinely pull that out?!

I totally get the problem that "the abuser knows the iCloud password and can use the FindMyPhone feature to track the victim", or "the abuser convinced the victim to install an app that would track the victim without their consent". But I am genuinely wondering how much GrapheneOS protects against that.

> That sounds like an NSO-level attack, right?

There are many tiers of far easier remote attacks far easier than exploiting an up-to-date iPhone through iMessage of WhatsApp. It doesn't mean that's what happened but it's often not something that's extremely difficult. Many people use phones with years of missing security patches. It's getting increasingly easy to exploit those in the age of LLMs.

Regardless, it sounds more like a social engineering attack tricking someone into installing an invasive app and granting invasive permissions to it.

> I doubt abusers routinely pull that out?!

They do regularly use social engineering to trick their partners into setting up stalkerware or permitting it to be installed. Getting a new phone and accounts is a very helpful for people who are victims of it. They've often given access to their accounts and devices without knowing how to fully get rid of it. Reclaiming the existing devices and accounts is far easier if they have a clean one to start from where they can get technical help. It doesn't specifically need to be a GrapheneOS device, but it's a good choice in general and doesn't require being technically savvy to use or even install it.

> Many people use phones with years of missing security patches

Right, yeah that's actually a good reason to use GrapheneOS.

> It doesn't specifically need to be a GrapheneOS device, but it's a good choice in general and doesn't require being technically savvy to use or even install it.

I totally agree here. Very good choice, and I would argue that a "normal" person wouldn't make the difference between GrapheneOS with sandbox Play Services and stock Android. Installing may be intimidating, even though the GrapheneOS installer is extremely impressive (it just works and doesn't require any knowledge). Still normies tend to get intimidated just from the idea of reinstalling their system :-).

> That sounds like an NSO-level attack, right?

Not really, these are available to any script kiddy as long as unpatched phones and software exists. It takes some initial effort to find them out, but that is it.

And I remember similar attacks floating around few years ago even outside domestic violence situation.

It's an advertisement. That's pretty much the difference, the company selling these phones has a very high margin for essentially resell of Google phones with reflash of GrapheneOS.
I mean, some obvious things are there in the article, IMHO -

- App isolation and hidden profiles (up to 32 separate profiles)

- Verified Boot (tamper detection on every startup)

So you can do stuff on there that's not going to tip off someone who's controlling enough to demand to see your phone, and so you'll at least be tipped off if someone compromises it.

> hidden profiles (up to 32 separate profiles)

I am a happy user of GrapheneOS, I don't know about "hidden" profiles. I am not sure what they are talking about.

> App isolation

That's an Android thing, not specific to GrapheneOS.

> Verified Boot (tamper detection on every startup)

That's an Android thing, not specific to GrapheneOS.

Indeed, whenever I reboot (which is very frequently, because Mastodon will only open, not reopen. If I close it, I need to reboot before using it again) I see the tamper detection. It warns me that I'm using GrapheneOS, not Android.
Yeah that's telling you that you are using custom signing keys (the ones of GrapheneOS, which should be compared once with those published on GrapheneOS' website).

Stock Android runs the tamper detection just the same; they just don't warn about the custom keys because the keys are not custom, they are the ones expected by the manufacturer :-).